LWN.net Logo

Java: applet privilege escalation

Package(s):sun-jdk sun-jre blackdown-jdk blackdown-jre CVE #(s):
Created:June 20, 2005 Updated:June 22, 2005
Description: Both Sun's (v < 1.4.2.08) and Blackdown's (v < 1.4.2.02) JDK and JRE may allow untrusted applets to elevate privileges. A remote attacker could embed a malicious Java applet in a web page and entice a victim to view it. This applet can then bypass security restrictions and execute any command or access any file with the rights of the user running the web browser.
Alerts:
SuSE SUSE-SA:2005:032 2005-06-22
Slackware SSA:2005-170-01 2005-06-19
Gentoo 200506-14 2005-06-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds